Rodeo
Get started

LT Harper Recruitment Group

Incident Response Lead (DFIR)

England
£90k – £110k/yr
Posted 1 day ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Incident Response Lead (DFIR) - Hybrid - Can be based anywhere in the UK - Up to £110k

The opportunity:

Do you want to lead the response to incidents that matter nationally?

A Cyber Consultancy is looking for an Incident Response Lead to join its Cyber Response Services team, reporting directly to the head of cyber response. This is a hands-on operational leadership role with a clear route into service line leadership. The team cover industries such as government, critical infrastructure and large enterprise, from ransomware through to advanced network intrusions. You will lead case managers and practitioners, stay technical in the forensics, and have a real say in how the practice grows.

Your benefits:

  • Up to £110k salary
  • Funded certifications and a structured training programme
  • Exposure to nationally significant incidents across government and CNI
  • Defined progression into senior leadership of a fast-growing capability
  • Hybrid working from London or Manchester hubs
  • Pension contribution and private healthcare

Your responsibilities as an Incident Response Lead will be to:

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

  • Manage and coordinate a portfolio of cyber security incidents for clients, working closely with the head of cyber response
  • Lead a team of case managers and practitioners through the full incident lifecycle: scoping, triage, containment, evidence preservation, eradication and recovery
  • Carry out and quality-assure digital forensics on disk, volatile memory, network traffic and log data
  • Own the commercial side of engagements, including scoping, costing, financial management and risk
  • Help clients stand up or mature their own IR capability through playbooks, maturity assessments and tabletop exercises
  • Drive the development of in-house cyber response tooling, lab environments and operating procedures
  • Mentor junior team members and shape the team's learning and development
  • Contribute to bids and proposals, and maintain a current view of the threat landscape for clients
  • Take part in an on-call rotation and be ready to travel at short notice, sometimes for two to three weeks at a time

As an Incident Response Lead you will ideally have:

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job
  • Significant experience managing complex cyber security incidents end to end, including leading a rapid deployment incident response team
  • Strong digital forensics competency, with advanced experience of tools such as X-Ways, EnCase, FTK, AXIOM/IEF or Cellebrite, and of preserving cloud data and encrypted evidence
  • Technical depth in at least one of network and log analysis, Linux or Mac forensics, memory forensics, malware reverse engineering or mobile forensics
  • A working programming skillset (Python preferred) and solid knowledge of enterprise Windows, Active Directory and Linux environments
  • Excellent written and verbal communication, with the ability to guide senior non-technical stakeholders through a live incident
  • Certifications such as CCIM, GCIH, CRIA, CCNIA, CCHIA, GCFA or GNFA are highly desirable, as are CISSP, CISM or CISA
  • Current SC or DV clearance, or eligibility and willingness to obtain it

If you are interested in this role, please contact me at c.burn@ltharper.com

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Location

England, United Kingdom

Sign up to applySee more jobs like this